Tell us, and we will not come after you.
If you have found a security problem in GovExpress, we want to hear about it. This page says exactly what is in scope, what protection you have, how fast we move — and, up front, that we do not pay for reports.
02 — HOW TO REPORT
Email security@govexpress.ai.
That address is the only reporting channel. Please do not open a public issue, post it, or tell us on social media before the window below has run. The machine-readable version of this policy is at /.well-known/security.txt.
A useful report has:
- The affected host and URL, and the date and time you tested.
- What the vulnerability is, and what an attacker gets out of it.
- Steps to reproduce it — enough that we can see it ourselves.
- Any proof-of-concept code, request, or screenshot. Redact anyone else’s data before you send it.
- How you would like to be credited, if you would like to be.
Write in English if you can. If you cannot, send it anyway — we would rather translate than miss it.
03 — WHAT WE COMMIT TO
We acknowledge your report, by a human, to the address you sent it from.
We tell you whether we have reproduced it, how we have rated the severity, and what we intend to do.
We keep you updated as it progresses, and we tell you when it ships.
The coordinated disclosure window closes and you are free to publish, fixed or not.
If a report is a duplicate, out of scope, or something we have decided to accept as a risk, we will say so plainly and explain why rather than letting the thread go quiet.
04 — COORDINATED DISCLOSURE
We ask you to hold the finding private for 90 days from the day you report it. After that you may publish whatever you like, whether or not we have fixed it. The clock does not restart, and we will not ask you to extend it except by agreement — a request you are free to refuse.
If a fix ships earlier and you want to publish earlier, tell us and we will almost certainly say yes. If we have not fixed it by day 90, that is our failure to disclose, not yours.
We will credit you by name or handle in the fix note if you want the credit, and stay quiet about you if you do not.
05 — IN SCOPE
Anything else with our name on it is out of scope by default. If you think something ought to be in scope, ask before you test it.
OUT OF SCOPE
- Anything hosted by a third party we do not control — our payment processor, our email provider, our source-control host. Report those to them; we will help you find the right address.
- Findings that are only a missing best-practice header, a cookie flag, or a TLS configuration preference, with no demonstrated impact. Our own security page already lists the headers we have not shipped yet.
- Missing SPF, DKIM, or DMARC records, and email spoofing without a demonstrated path to harm.
- Denial of service, volumetric testing, brute force, and anything that degrades the service for other people.
- Social engineering, phishing, or physical attacks against us, our customers, or our vendors.
- Automated scanner output submitted without a working proof of concept or an explanation of impact.
- Self-XSS, clickjacking on pages with no state-changing action, missing rate limits with no demonstrated abuse, and version-banner disclosure.
- Vulnerabilities requiring a rooted or jailbroken device, a physically compromised machine, or a browser two or more major versions out of date.
- The content of our public federal data. If a score or a figure is wrong, that is a correction request, not a vulnerability — write to us and we will fix it or show you the source record.
06 — RULES OF ENGAGEMENT
- Use only accounts you own or have explicit permission to test. Never touch another customer’s data.
- Stop as soon as you have confirmed a vulnerability. Do not pivot, do not escalate further than needed to prove impact, and do not exfiltrate data.
- If you access personal or confidential data by accident, stop, tell us immediately, and delete every copy.
- Do not modify or delete data, and do not degrade the service for anyone else.
- Keep the finding between us until the disclosure window below has run.
Stay inside these and the safe harbour below applies. Step outside them — pull other people’s data, break the service, extort us — and it does not.
07 — SAFE HARBOUR
If you research in good faith and follow this policy, we will not take legal action against you, and we will not ask anyone else to.
Specifically, we consider that research to be:
- Authorized under the Computer Fraud and Abuse Act and any equivalent state or foreign computer-crime law, so it is not unauthorized access.
- Exempt from the anti-circumvention provisions of the Digital Millennium Copyright Act, and we will not bring a DMCA claim over it.
- Permitted under our terms of service, whose restrictions on probing and scanning we waive for the duration and scope of your testing.
If a third party brings legal action against you for research that followed this policy, we will make that fact known publicly and to the court on request.
Act in good faith and we will assume good faith. If you are unsure whether something is in scope, email security@govexpress.ai and ask first — asking never counts against you.
This safe harbour is our commitment, and it binds us. It cannot bind a prosecutor, a court, or a third party whose systems you also touch, and nothing here is legal advice.
08 — THERE IS NO BUG BOUNTY
We do not pay for vulnerability reports. There is no bounty, no reward table, and no swag.
We are saying it here, at the top of the page you would read before starting, rather than at the end of a thread after you have done the work. If being unpaid makes this not worth your time, that is a completely reasonable conclusion and we would rather you reach it now.
What we do offer is a fast, human response, credit if you want it, a straight answer about what we are going to do, and a disclosure window we do not move. If we ever launch a paid programme, it will be announced on this page and it will not apply retroactively — so a report sent today is sent on today's terms.